QUYFIN
Privacy Policy
Last updated: August 2026
QUYFIN – Research Observatory on Biodiversity Dynamics (“QUYFIN”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal data of visitors, collaborators, researchers, partners and other individuals who interact with our website and activities.
This Privacy Policy explains how we collect, use, store and protect personal data when you visit our website, contact us, submit information through our online forms or otherwise interact with QUYFIN.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Greek and European data protection legislation.
1. Data Controller
The data controller responsible for the processing of personal data through this website is:
QUYFIN – Research Observatory on Biodiversity Dynamics
[Legal entity / Company name]
[Registered address]
Greece
Email: [contact@quyfin.com]
Website: [www.quyfin.com]
For any questions concerning this Privacy Policy or the processing of your personal data, you may contact us using the details above.
2. Personal Data We May Collect
Depending on how you interact with our website, we may collect the following categories of personal data:
Information you provide directly
When you contact us or submit a form, we may collect information such as:
- Name and surname
- Email address
- Telephone number
- Organisation, institution or company
- Professional role or position
- Information included in your message or enquiry
- Project or collaboration information you voluntarily provide
Please avoid submitting sensitive personal information unless it is necessary for your communication with us.
Technical information
When you access our website, certain technical information may be processed automatically, including:
- IP address
- Browser type and version
- Device type
- Operating system
- Referring website or source
- Pages visited
- Date and time of access
- General interaction and usage information
Some of this information may be collected through cookies or similar technologies, subject to your consent where required.
3. How We Use Personal Data
We may process personal data for the following purposes:
- To respond to enquiries and requests
- To communicate with researchers, organisations, farmers, land users, municipalities, companies and potential partners
- To evaluate potential research or project collaborations
- To provide information about QUYFIN and its activities
- To operate, maintain and improve our website
- To ensure the security and technical integrity of our website
- To understand how visitors interact with our website
- To comply with legal or regulatory obligations
- To establish, exercise or defend legal claims where necessary
Personal data collected through the website will not be used for purposes incompatible with those described in this Privacy Policy.
4. Legal Basis for Processing
Under the GDPR, we process personal data only when a valid legal basis exists.
Depending on the circumstances, processing may be based on:
Consent – where you have given us permission to process your personal data for a specific purpose.
Legitimate interests – where processing is necessary for the legitimate operation, security, communication or development of QUYFIN, provided that these interests do not override your fundamental rights and freedoms.
Pre-contractual or contractual necessity – where processing is necessary in connection with a potential or existing collaboration, agreement or service.
Legal obligation – where processing is required to comply with applicable law or regulatory requirements.
Where processing is based on consent, you may withdraw your consent at any time.
5. Contact and Collaboration Forms
When you submit information through a contact, collaboration or project-related form on our website, the information you provide will be used primarily to review and respond to your request.
Depending on the nature of your enquiry, your information may be shared internally with the appropriate members of the QUYFIN team.
Submitting a form does not automatically create a contractual, research or commercial relationship with QUYFIN.
6. Research and Biodiversity Data
QUYFIN’s activities may involve the collection and analysis of ecological, environmental, agricultural and biodiversity data.
Such information may include observations relating to plant populations, insect populations, pollinator behaviour, soil characteristics, microbial communities, geographic areas and ecological interactions.
Environmental and biodiversity data does not necessarily constitute personal data under the GDPR. However, where research or monitoring information can be associated with an identifiable individual, farm operator, landowner, collaborator or other natural person, QUYFIN will process that information in accordance with applicable data protection requirements.
Specific research projects may be governed by additional privacy notices, research protocols, agreements or consent procedures where appropriate.
7. Cookies and Similar Technologies
Our website may use cookies and similar technologies to ensure proper functionality, improve performance, understand website usage and, where applicable, provide analytics services.
Cookies may include:
- Strictly necessary cookies
- Functional cookies
- Analytics or performance cookies
- Third-party cookies, where applicable
Where required by law, non-essential cookies will only be activated after you provide your consent.
You may modify or withdraw your cookie preferences at any time through the cookie settings available on the website.
For more information, please refer to our Cookie Policy, where available.
8. Third-Party Services
Our website may use third-party technology providers for services such as:
- Website hosting
- Security and performance
- Analytics
- Maps and geographic visualisations
- Embedded media
- Communication or form processing
- Research or data visualisation tools
Where these providers process personal data on our behalf, we take reasonable steps to ensure that appropriate contractual and technical safeguards are in place.
Some third-party services may process data outside the European Economic Area (“EEA”). Where this occurs, appropriate safeguards will be implemented where required by applicable data protection law.
9. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected.
The appropriate retention period depends on the nature of the information, the purpose of processing and any applicable legal, contractual or research requirements.
Contact and enquiry information may be retained for a reasonable period to allow us to manage communications, maintain appropriate records and follow up on potential collaborations.
Where personal data is no longer required, it will be deleted, anonymised or securely archived where legally necessary.
10. Data Security
QUYFIN takes appropriate technical and organisational measures designed to protect personal data against:
- Unauthorised access
- Accidental loss
- Destruction
- Alteration
- Disclosure
- Misuse
While we take reasonable measures to protect information, no internet-based system or electronic storage method can guarantee absolute security.
11. Your Rights Under the GDPR
If the GDPR applies to the processing of your personal data, you may have the right to:
- Request access to your personal data
- Request correction of inaccurate or incomplete information
- Request deletion of your personal data
- Request restriction of processing
- Object to certain types of processing
- Request data portability where applicable
- Withdraw your consent at any time where processing is based on consent
- Lodge a complaint with the competent data protection authority
The exercise of certain rights may be subject to conditions or limitations established by applicable law.
To exercise your rights, please contact us at:
[privacy@quyfin.gr]
We may need to verify your identity before responding to certain requests.
12. Supervisory Authority
You have the right to lodge a complaint with the competent supervisory authority if you believe that your personal data has been processed in violation of applicable data protection legislation.
In Greece, the competent authority is the:
Hellenic Data Protection Authority (HDPA)
Athens, Greece
13. Links to External Websites
Our website may contain links to websites operated by universities, research institutions, public authorities, project partners or other third parties.
QUYFIN is not responsible for the privacy practices, security or content of external websites.
We encourage you to review the privacy policies of any third-party website you visit.
14. Children’s Privacy
The QUYFIN website is not intended to knowingly collect personal data from children through its general contact or collaboration services.
Where a specific educational, citizen-science or research activity involves minors, appropriate privacy information, consent procedures and safeguards will be implemented separately where required.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our activities, website functionality, technologies or applicable legal requirements.
The latest version will always be published on this page together with the date of the most recent update.
16. Contact Us
For questions about this Privacy Policy, the processing of your personal data or the exercise of your data protection rights, please contact:
QUYFIN – Research Observatory on Biodiversity Dynamics
Email: [contact@quyfin.com]
Website: [www.quyfin.com]